A malicious ZIP archive masquerading as the résumé of Zhang Yuguang, presented as a Beijing Institute of Technology network-engineering graduate, was used to target researchers interested in China’s defense-technology sector. Opening the lure resulted in deployment of VShell, a legitimate remote-access tool that can be abused as a backdoor, enabling remote control of compromised systems.
Reported infrastructure and artifacts include IP address 38.207.178.192, ports 50812 and 50813, and HTTP resources named EasyConnectUpdata_Log.txt and MySQL_LOG.txt. Defenders should investigate connections to that infrastructure and review endpoints for TEMPde.log, the string YtWzxwZimsZoeMen, and associated résumé-themed ZIP files; the available reporting does not attribute the campaign or identify confirmed victims.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
SOCRadar reported a SNOWLIGHT campaign that scanned more than 9,990 hostnames across 104 country-code domains and targeted government and commercial infrastructure in over 100 countries, with Taiwan as its principal target. The operators allegedly exploited exposed services including Apache Tomcat, cPanel/WHM, Confluence, Exchange ProxyShell, and WebLogic-class targets using staging infrastructure led by 130.94.17[.]180, first observed on 2026-06-09.
Reporting identified professors and laboratory personnel researching applied AI, electrical grids, and renewable energy as targets of the fake Zhang Yuguang résumé campaign. It also identified a likely intended recipient as an academic in mainland China, while noting that no operator or ultimate objective was established.
Researchers detailed that the fake resume executable performs anti-analysis checks, downloads encrypted SNOWLIGHT shellcode for in-memory execution, and receives a 4.65 MB payload that launches VShell. The report also published hashes for the loader, shellcode, encrypted response, and VShell payloads, and documented encrypted VShell registration with 38.207.178.192.
Researchers published observables tied to a ZIP archive purporting to be a Beijing Institute of Technology network-engineering graduate resume for Zhang Yuguang, including file hashes, 38.207.178.192, ports 50812 and 50813, and URLs for EasyConnectUpdata_Log.txt and MySQL_LOG.txt.
A malware-delivery campaign used a fake resume referencing China’s defense-technology sector as a social-engineering lure, resulting in installation of the VShell remote-access tool. No actor, victim, or affected organization was identified.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcereddit.com
Open sourceblog.himanshuanand.com
Open sourcesocradar.io
Open sourceunitracker.aspi.org.au
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.